Summary
- CERT-EU’s September cyber brief highlights increased LLM-jacking, in which criminals steal premium AI access or compromise cloud systems to run unauthorised workloads.
- Google has observed underground demand for AI accounts and infrastructure as criminals seek to avoid the cost of premium models and compute.
- Model credentials, API keys, cloud permissions, and GPU capacity are becoming assets that need the same security discipline as other privileged production resources.
Enterprise adoption of artificial intelligence is creating another class of cyber asset worth stealing, as attackers increasingly target the accounts, credentials, and cloud infrastructure that provide access to expensive models and computing capacity.
The trend appears prominently in CERT-EU’s September cyber brief, published on 2 October after analysing 358 open-source reports. The EU cybersecurity service highlights increased LLM-jacking alongside a wider pattern of malicious activity involving AI systems.
LLM-jacking applies a familiar criminal model to newer infrastructure. Rather than paying for premium generative AI services or high-performance computing, attackers steal legitimate credentials, buy compromised accounts, or break into cloud environments and consume somebody else’s resources.
Google Threat Intelligence Group has documented related activity, including criminals seeking premium AI accounts and compromised cloud resources capable of running unauthorised workloads. As model access and compute become more expensive, avoiding those costs creates an incentive comparable with the economics that previously drove cryptojacking.
AI systems create valuable credentials
Businesses have spent years learning to protect administrator passwords, cloud tokens, payment credentials, and software-development secrets, while AI adoption adds another collection of credentials whose theft can create both direct expense and wider security exposure.
An API key may provide metered access to a model service, a developer account can unlock coding tools, and a compromised cloud role may expose GPU infrastructure powerful enough to run models locally. Enterprise AI systems may also sit close to internal documents, software repositories, identity systems, and automation tools.
The value is therefore not limited to avoiding subscription fees. A stolen account can provide access to data already supplied to an AI service, while compromised infrastructure can become a platform for additional malicious activity under somebody else’s cloud bill and identity.
CERT-EU’s September brief points to underground sellers offering discounted access to premium AI tools, sometimes alongside replacement credentials if an account stops working. It also records wider incidents in which AI services, agents, and infrastructure appeared elsewhere in attack chains.
One case involved METR, an organisation that evaluates frontier AI systems, where attackers exploited an authentication weakness in exposed cloud infrastructure and obtained an API key. CERT-EU’s summary says roughly $600,000 of AI credits were consumed over a period of three weeks.
Cost monitoring becomes a security control
The defensive response is less novel than the technology being stolen, because organisations already have controls designed for valuable production systems. Least-privilege access, short-lived credentials, secrets management, workload monitoring, network restrictions, and rapid revocation all apply to AI environments as readily as they do elsewhere in the cloud.
Spending data can also become part of threat detection when usage is directly linked to compute consumption. Unexpected GPU activity, sharp changes in model traffic, access from unfamiliar locations, or unusual token consumption may reveal compromise before a conventional security alert appears.
The problem becomes harder as companies host more models themselves, because public AI services can apply their own fraud detection and account controls while an organisation operating private infrastructure inherits greater responsibility for monitoring the underlying compute.
Google’s broader threat research also shows adversaries moving from basic prompting towards more automated and agentic workflows in reconnaissance, credential theft, software compromise, and other parts of the attack process. AI is therefore appearing on both sides of the transaction: criminals use it to support attacks while simultaneously treating access to AI itself as something worth stealing.
CERT-EU’s monthly brief is based on open sources and does not establish the prevalence of LLM-jacking across every European organisation, so it should not be read as an incident census. Its value lies in showing that theft of AI access has moved into mainstream threat reporting alongside better-established forms of cloud abuse.
As generative AI shifts from experimentation into production systems, the security boundary shifts with it. Accounts, credits, models, agents, and GPU infrastructure now carry enough operational and financial value to attract attackers, which makes them part of the same privileged environment organisations already know they need to monitor closely.












